Malicious PDF — malware analysis report

Static analysis result for SHA-256 ca9dd62a995f5524…

MALICIOUS

PDF

19.3 KB Created: 2019-04-30 04:37:02 +01:00 Authoring application: mPDF 5.7
MD5: dcdf29bb3118f4b54e809faa6784e7ce SHA-1: 97ced855ed7a433f29835a96f22ab64df0f1a165 SHA-256: ca9dd62a995f55242f9a3964c482bacb5899f37356e9e1062f488f740240b9db
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded URLs, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. While the URLs themselves are currently marked as benign, the sheer volume and structure suggest a malicious intent, likely for SEO spam or to distribute further payloads. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1090097096091090093/The-Inscrutable-Charlie-Muffin-Charlie-Muffin-3-by-Brian-Freemantle.pdf
    • http://loaminoo.linkpc.net/1090097096091090095/Charlie-Muffin-s-Uncle-Sam-Charlie-Muffin-4-by-Brian-Freemantle.pdf
    • http://loaminoo.linkpc.net/1090097096091099090/Here-Comes-Charlie-M-Charlie-Muffin-2-by-Brian-Freemantle.pdf
    • http://loaminoo.linkpc.net/1090097096093091098/Red-Star-Burning-Charlie-Muffin-15-by-Brian-Freemantle.pdf
    • http://loaminoo.linkpc.net/1090097096093091090/Charlie-Muffin-s-Miracle-Mouse-by-Dick-King-Smith.pdf
    • http://loaminoo.linkpc.net/1090097096090094092/Muffin-But-Murder-Merry-Muffin-Mystery-2-by-Victoria-Hamilton.pdf
    • http://loaminoo.linkpc.net/1090097096092092091/5-BOOKS-BY-MUFFIN-by-Muffin.pdf
    • http://loaminoo.linkpc.net/4095092094096094/Charlie-and-the-Great-Glass-Elevator-Charlie-Bucket-2-by-Roald-Dahl.pdf
    • http://loaminoo.linkpc.net/1098094092093091/Charlie-and-the-Great-Glass-Elevator-Charlie-Bucket-2-by-Roald-Dahl.pdf
    • http://loaminoo.linkpc.net/7092096092091096/Je-suis-Charlie-Chronologie-de-l-attaque-terroriste-contre-Charlie-Hebdo-by-Josh-Seyward.pdf
    • http://loaminoo.linkpc.net/7097096097096095/Obituary-of-Charlie-Whitehorse-The-Return-of-Charlie-as-a-Cardinalis-Equidae-by-MR-Glenn-Andrew-Dykstra.pdf
    • http://loaminoo.linkpc.net/1090097096090095092/Muffin-Man-by-Brad-Whittington.pdf
    • http://loaminoo.linkpc.net/1090097096091096098/The-Muffin-Fiend-by-Daniel-Pinkwater.pdf
    • http://loaminoo.linkpc.net/3093099096094093/Muffin-Top-The-Hartigans-2-by-Avery-Flynn.pdf
    • http://loaminoo.linkpc.net/1090097096092090096/Molly-the-Muffin-Fairy-by-Tim-Bugbird.pdf
    • http://loaminoo.linkpc.net/5096099099093090/Long-Hollow---A-Charlie-LeBeau-Mystery-Charlie-LeBeau-Mysteries-Book-1-by-Gregory-Heitmann.pdf
    • http://loaminoo.linkpc.net/1090095096093094/Muffin-House-of-Assignation-SEries-by-Kimmie-Thomas.pdf
    • http://loaminoo.linkpc.net/4099097095095091/Charlie-Joe-Jackson-s-Guide-to-Planet-Girl-Charlie-Joe-Jackson-5-by-Tommy-Greenwald.pdf
    • http://loaminoo.linkpc.net/3097099097091093/Charlie-Joe-Jackson-s-Guide-to-Making-Money-Charlie-Joe-Jackson-4-by-Tommy-Greenwald.pdf
    • http://loaminoo.linkpc.net/1098095090095098/Charlie-The-Cavalier-Begs-for-Attention-Rhyming-Bedtime-Story-Picture-Book-for-Beginner-Readers-and-Early-Learning-About-Feeling-Safe-When-Loved-Ones-Puppet-Charlie-the-Cavalier-Books-1-by-Lisa-M-Rusczyk.pdf
    • http://loaminoo.linkpc.net/7097096097096095/Obituary-of-Charlie-Whitehorse-The-Re